



Ask any incident responder what the attacker did first after gaining an initial foothold, and the answer is almost always the same: they went after privileged credentials. Domain administrator accounts, service accounts with standing access to production databases, shared root credentials passed around on sticky notes — these are not hypothetical risks. They are the actual pivot points in the vast majority of enterprise breaches investigated every year.
For Indian enterprises navigating a threat landscape that is intensifying alongside rapid digital growth, Privileged Access Management (PAM) is no longer a luxury item on the security roadmap. It is a foundational control — one that the Digital Personal Data Protection (DPDP) Act 2023 and CERT-In’s 2022 directions make increasingly difficult to defer.
Privileged accounts — administrator accounts, service accounts, SSH keys, API tokens, and break-glass credentials — hold the keys to your crown jewels. Compromise a standard user account and an attacker is sandboxed. Compromise a Domain Admin or a database SA account and they have unfettered access to every system that account can reach.
Attackers know this, and their playbooks reflect it. The MITRE ATT&CK framework documents dozens of techniques under the Credential Access and Privilege Escalation tactics specifically designed to harvest, abuse, and maintain privileged access. Techniques such as OS Credential Dumping (T1003), Kerberoasting (T1558.003), and Pass-the-Hash (T1550.002) are not exotic zero-days — they are commodity tools that any moderately skilled threat actor can deploy within minutes of getting their first toehold.
What makes the Indian enterprise environment particularly vulnerable is a confluence of legacy infrastructure, rapid cloud adoption, and talent gaps in IAM that leave privileged access sprawling, unmonitored, and chronically under-rotated.
During security assessments across mid-market and large enterprise environments in India, the same patterns appear repeatedly:
These are not edge cases. They are endemic to organisations that treated identity security as an afterthought while racing to digitise operations.
A PAM programme is not a single product purchase. It is a set of capabilities that must be designed, implemented, and operated continuously. Here is what a mature PAM posture looks like:
Every privileged credential — Windows local admin, Linux root, database SA, network device enable password, cloud access key — must be stored in a dedicated vault with strong encryption. Passwords should rotate automatically on a schedule (or after every use for highly sensitive accounts) so that a compromised credential is usable only for a narrow window.
Standing privileged access is a risk multiplier. JIT access means privileges are elevated only when needed, for a bounded time window, and automatically revoked when that window closes. Just-Enough Access (JEA) means the elevated role grants only the specific permissions required for the task — not full domain admin to install a printer driver.
Every privileged access request should require MFA, separate from the standard user MFA. Privileged MFA should ideally use phishing-resistant methods: hardware tokens or FIDO2 passkeys rather than SMS OTP, which remains vulnerable to SIM-swap attacks — a threat that has specifically targeted Indian telecom subscribers.
Every privileged session — RDP, SSH, database console, cloud CLI — should be recorded and available for audit. Session recording is the PAM equivalent of CCTV: a deterrent, an investigation tool, and increasingly a compliance requirement.
Static rules (“alert if admin logs in after 10 PM”) are necessary but not sufficient. Behavioural baselines should be built for each privileged account so that unusual access patterns — a service account suddenly querying HR tables, a network admin running bulk export commands — trigger analyst review in real time.
Every privileged account that no longer has an active, named owner should be revoked. This sounds obvious, but in practice most organisations have dozens of orphaned accounts accumulated over years of staff turnover, project completions, and system migrations.
India’s regulatory environment in 2026 makes PAM a compliance imperative, not just a security best practice.
The DPDP Act 2023 requires Data Fiduciaries to implement reasonable security safeguards to protect personal data. Access to personal data stores — HR systems, customer databases, healthcare records, financial data — is almost always mediated by privileged accounts. Uncontrolled privileged access to personal data represents a direct compliance gap. The Act’s breach notification obligations (reporting to the Data Protection Board when a breach is likely to harm data principals) also require that organisations can quickly determine what data was accessed and by whom — something impossible without session logs and access audit trails.
CERT-In’s 2022 directions require organisations to maintain ICT system logs for 180 days, stored in India, and to report certain cyber incidents within 6 hours of detection. For a privileged access breach — which is a reportable incident category — the 6-hour reporting window means you need privileged session logs that are already ingested, indexed, and searchable. An organisation discovering a breach and scrambling to locate scattered server logs on the morning it needs to file a CERT-In report is in an extremely difficult position.
PAM controls, combined with a properly configured SIEM, make that 6-hour window achievable. Without them, it is not.
Deploying a PAM vault solves the credential storage and session management problem. But visibility into what those privileged sessions are actually doing — and how they correlate with other events across your environment — requires a SecOps platform that can ingest, correlate, and surface the signal. That is the role of PrahiX Ora, the unified SecOps platform that PJ Networks deploys and operates for enterprise clients.
SIEM with MITRE ATT&CK correlation: Ora’s SIEM ingests logs from your PAM vault alongside endpoint telemetry, firewall events, directory service audit logs, and cloud trail data. Correlation rules mapped to MITRE ATT&CK techniques surface high-fidelity alerts for privileged credential abuse — Kerberoasting attempts, pass-the-hash lateral movement, anomalous service account activity — rather than generating low-context log noise. Ora’s graph-based attack storyline reconstruction links events across systems so analysts see the full attack chain, not isolated alerts. Tiered retention (hot, cold, and archive storage) supports CERT-In’s 180-day in-country log retention direction without requiring organisations to overbuild their own storage infrastructure.
NMS with unified observability: For enterprises running multi-vendor networks — a common reality across Indian mid-market — Ora’s Network Management System provides a unified view across FortiGate firewalls, switches, wireless access points, and SD-WAN links. LLDP/CDP topology discovery means you have an accurate picture of your network; ML-based anomaly detection flags unusual traffic patterns, including lateral movement between network segments that privileged sessions should not be crossing.
Video surveillance (VMS) under one pane: For manufacturing, retail, and multi-site enterprises, Ora’s video surveillance module (supporting ONVIF, Hikvision, and Dahua camera ecosystems) brings physical security event correlation under the same operations view. A privileged user accessing a data centre at an unusual hour can be correlated with a camera event at the server room door — closing a gap that purely logical PAM controls cannot address.
SOAR for the 6-hour CERT-In window: Ora’s SOAR module provides playbook automation with pre-built connectors and automated response actions, including pushing blocklists directly to FortiGate. When a privileged account is flagged for credential abuse, an automated playbook can isolate the compromised session, revoke the associated credential from the vault, notify the SOC, and draft the preliminary CERT-In incident report — all before a human analyst has finished their first coffee of the morning. That is what makes the 6-hour reporting window realistic rather than aspirational.
If you are operating a fragmented estate where privileged session logs live in one system, network events in another, and physical access records in a third, Ora brings those streams together. PJ Networks is PrahiX’s primary field deployment and operations partner; we implement and run the platform for enterprise clients who want enterprise-grade SecOps without standing up an in-house platform team.
PJ Networks’ 24/7 NOC/SOC team operates across multiple layers of your privileged access controls:
Every month that passes without a structured PAM programme is a month in which an attacker who gains any foothold in your environment can escalate to domain administrator without triggering a single alert. The average dwell time for attackers in enterprise networks — the time between initial access and detection — remains measured in weeks. That is weeks during which unmonitored privileged access provides unrestricted freedom to exfiltrate data, move laterally, and establish persistence.
Under the DPDP Act, a breach involving personal data that could have been prevented by reasonable access controls is not just a security failure — it is a compliance failure with regulatory and reputational consequences. The Data Protection Board has not yet established its full enforcement posture, but organisations that can demonstrate mature access controls, including PAM, will be in a substantially stronger position than those that cannot.
The question Indian enterprise CISOs need to answer is not whether to implement PAM, but how quickly they can close the most critical gaps. A phased approach — starting with credential discovery and vaulting for Tier-0 assets, adding JIT and session recording in the second phase, and operationalising anomaly detection in the third — is realistic even in constrained budget environments.
PJ Networks offers a structured PAM readiness assessment that maps your current privileged access landscape against the NIST SP 800-207 Zero Trust principles, DPDP Act obligations, and CERT-In technical direction requirements. The engagement delivers a prioritised remediation roadmap with effort and risk ratings for each control gap, giving your CISO and board a clear picture of where the organisation stands and what investment is needed to reach a defensible posture.
If your organisation is operating with shared admin credentials, no session recording, and privileged accounts that have not been reviewed since the last system migration, the gap between your current posture and what regulators and auditors will expect is growing every quarter.
To schedule a PAM readiness assessment or to learn more about how PJ Networks’ managed security services — including 24/7 NOC/SOC, FortiGate management, ZTNA deployment, and Ora-powered SecOps — can help close that gap, contact the PJ Networks team at pjnetworks.com.